← All views

CVSS versus consequence paths

A reviewed comparison of published CVSS baselines with canonical consequence-path directions.

CVSS may understate reachable consequence.

These records reach a higher canonical Path Score band than their published CVSS baseline alone communicates.

  1. Undocumented CloudSail remote-access backdoor

    Unitree · Robotics / humanoid

    Device-control safety · Fleet control plane

    Published baseline
    CVSS v3.1 6.6 MEDIUM
    Path Score
    EMERGENCY
  2. GAZEploit remote keystroke inference

    Apple · Smart glasses / AR

    Perception privacy · Account authority

    Published baseline
    CVSS v3.1 5.3 MEDIUM
    Path Score
    CRITICAL
  3. BLE Wi-Fi configuration root takeover

    Unitree · Robotics / humanoid

    Fleet control plane

    Published baseline
    CVSS v3.1 8.2 HIGH
    Path Score
    EMERGENCY
  4. Static engineering credentials exposed in a mobile application

    Qardio · Wearable health

    Account authority

    Published baseline
    CVSS v3.1 6.6 MEDIUM
    Path Score
    CRITICAL
  5. One-click remote code execution via malicious deep link

    Meta · Smart glasses / AR

    Perception-to-action · Account authority

    Published baseline
    CVSS v3.1 8.8 HIGH
    Path Score
    CRITICAL
  6. Extractable firmware files

    Qardio · Wearable health

    Data privacy

    Published baseline
    CVSS v4.0 6.9 MEDIUM
    Path Score
    HIGH

CVSS may overstate reachable consequence.

These records retain their published CVSS baseline while the canonical consequence path supports a lower Path Score band.

  1. Insufficient audit logging

    Baxter · Medical IoT

    Observability and recovery

    Published baseline
    CVSS v3.1 10 CRITICAL
    Path Score
    MONITOR